ATT&CKSoftwareWinnti for Linux

Winnti for Linux

S0430

Malware.View on attack.mitre.org

About this malware

Winnti for Linux is a trojan, seen since at least 2015, designed specifically for targeting Linux systems. Reporting indicates the winnti malware family is shared across a number of actors including Winnti Group. The Windows variant is tracked separately under Winnti for Windows.

Techniques used8

Procedure examples8

TechniqueProcedure example
T1014
Rootkit

Winnti for Linux has used a modified copy of the open-source userland rootkit Azazel, named libxselinux.so, to hide the malware's operations and network activity.

T1027.013
Encrypted/Encoded File

Winnti for Linux can encode its configuration file with single-byte XOR encoding.

T1071.001
Web Protocols

Winnti for Linux has used HTTP in outbound communications.

T1095
Non-Application Layer Protocol

Winnti for Linux has used ICMP, custom TCP, and UDP in outbound communications.

T1105
Ingress Tool Transfer

Winnti for Linux has the ability to deploy modules directly from command and control (C2) servers, possibly for remote command execution, file exfiltration, and socks5 proxying on the infected host.

T1140
Deobfuscate/Decode Files or Information

Winnti for Linux has decoded XOR encoded strings holding its configuration upon execution.

T1205
Traffic Signaling

Winnti for Linux has used a passive listener, capable of identifying a specific magic value before executing tasking, as a secondary command and control (C2) mechanism.

T1573.001
Symmetric Cryptography

Winnti for Linux has used a custom TCP protocol with four-byte XOR for command and control (C2).

Groups that use it3

Campaigns0

None recorded.

References1

  1. Chronicle Winnti for Linux May 2019 Open source
    Chronicle Blog. (2019, May 15). Winnti: More than just Windows and Gates. Retrieved April 29, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.